CVE-2023-46805
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
⚠ KEVEPSS 100.0%
Description
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.
How to fix CVE-2023-46805
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2023-46805 being exploited?
Yes — CVE-2023-46805 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.